First published: Wed Apr 19 2023(Updated: )
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated user.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Modicon M580 Firmware | <4.10 | |
Schneider-electric Modicon M580 | ||
Schneider-electric Modicon M340 Firmware | <3.51 | |
Schneider-electric Modicon M340 | ||
Schneider-electric Modicon Momentum Unity M1e Processor Firmware | ||
Schneider-electric Modicon Momentum Unity M1e Processor | ||
Schneider-electric Modicon Mc80 Firmware | ||
Schneider-electric Modicon Mc80 | ||
Schneider-electric 140cpu65 Firmware | ||
Schneider-electric 140cpu65 | ||
Schneider-electric Tsxp57 Firmware | ||
Schneider-electric Tsxp57 | ||
Schneider-electric Bmep58s Firmware | ||
Schneider-electric Bmep58s | ||
Schneider-electric Bmeh58s Firmware | ||
Schneider-electric Bmeh58s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2023-25620.
The severity level of CVE-2023-25620 is medium (6.5).
The Schneider-electric Modicon M580 Firmware and Schneider-electric Modicon M340 Firmware are affected by CVE-2023-25620.
The CWE ID of this vulnerability is CWE-754.
Please refer to the official reference document provided by Schneider Electric for information on available fixes.